Privacy page · Effective July 22, 2026

Your models. Your numbers. Your business.

R-MAP is a decision platform, not a data business. This page says plainly what is stored, what never happens with it, who the third parties are, and how to get anything removed — written by the person who runs the servers. R-MAP is operated by R-MAP LLC (a Washington LLC), the controller of the data described here.

The R-MAP vault — a protected core surrounded by verified model screens
Protected by design · gated on the server
01 · What R-MAP handles

Stored only because the platform needs it.

Every item below exists to make an account, a membership, or a saved setup work — nothing is collected “because it might be useful later.”

On R-MAP’s servers

Account & membership

  • Email address your account identity and the only way support can reach you.
  • Password, hashed stored only as a bcrypt hash; the plain text is never stored or logged.
  • Membership status whether your subscription is active, set only by verified billing events.
  • Waitlist entries the email and interest you submit on the request form.
  • Saved lab scenarios setups a member explicitly saves to their account (☁ in the FX toolbar).
  • Scoring inputs when a member model computes an official score, the inputs are processed server-side to return the result — not used for anything else.
Only in your browser

Never sent anywhere

  • Lab inputs & sliders what you type into models is remembered in your browser’s local storage.
  • Page notes annotate-mode edits stay on your device, per page.
  • Palette & FX preferences colors, motion on/off, toolbar position — all local.
  • Session token a signed, self-expiring credential (7 days) held by your browser; signing out clears it.
02 · What R-MAP will not do

The hard lines.

These aren’t settings you have to find and switch off. They are how the platform is built.

No selling, no sharing

Your personal data is never sold, rented, or shared for advertising or marketing. There are no ad networks and no data brokers anywhere in the stack.

No tracking apparatus

No analytics SDKs, no tracking pixels, no fingerprinting. The only thing resembling a cookie is your own session token, which exists so you stay signed in.

No model training

Your registers, scenarios, and scores are not used to train machine-learning models — yours or anyone else’s.

No card numbers held

When billing goes live, payment details go directly to Stripe. Card numbers never touch, transit, or rest on R-MAP’s servers.

03 · Third parties

The short list, and what each one sees.

R-MAP runs on a deliberately small set of services. None of them receives your model data.

Infrastructure

AWS

The backend and database run on Amazon Web Services (US region). AWS hosts the encrypted infrastructure; it isn’t granted your data for its own use.

Billing · when live

Stripe

Processes membership payments as a PCI-compliant processor. R-MAP receives your subscription status and a customer reference — never your card number.

Website fonts

Google Fonts

The site’s typefaces load from Google’s font servers, which see the standard technical metadata of any web request (IP address, browser type). No account data is ever attached.

04 · Retention

Kept only as long as it serves you

  • Account data kept while your account exists; removed on request.
  • Saved scenarios kept until you delete them or your account.
  • Waitlist entries kept until launch outreach completes, or removed on request.
  • Session tokens expire on their own after 7 days; sign-out clears them immediately.
  • Local browser data yours to clear any time (FX toolbar ⟲, or your browser’s site-data controls).
05 · Security

The same rigor the models preach

  • HTTPS everywhere all traffic between you and R-MAP is encrypted in transit.
  • bcrypt hashing passwords are salted and hashed with a purpose-built algorithm.
  • Signed sessions tokens are HMAC-signed, time-limited, and compared in constant time.
  • Verified billing events membership flips only on cryptographically verified Stripe webhooks — never from the browser.
  • Server-side gating protected content and scoring IP are enforced on the server; there is no public URL that bypasses membership.
  • Least privilege the database user is scoped to exactly the access the platform needs.
06 · Your choices

Access, correction, removal — just ask.

No forms buried three menus deep. Requests go straight to the person who can act on them, typically within 1–2 business days.

See or fix

Access & correction

Ask what’s stored under your email, or have it corrected — reply comes from the maker, not a bot.

Delete

Removal

Ask for your account, waitlist entry, or saved scenarios to be deleted and it’s done — put “Privacy” in the subject line so it’s prioritized.

If this policy changes, the effective date at the top changes with it — materially different terms will be called out, not slipped in.